CVE-2025-27727
- EPSS 0.17%
- Published 08.04.2025 17:24:05
- Last modified 08.07.2025 16:28:26
Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.
- EPSS 0.21%
- Published 08.04.2025 17:24:01
- Last modified 07.07.2025 18:25:39
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2025-27481
- EPSS 0.07%
- Published 08.04.2025 17:23:59
- Last modified 08.07.2025 19:14:14
Stack-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to execute code over a network.
CVE-2025-27484
- EPSS 0.04%
- Published 08.04.2025 17:23:58
- Last modified 08.07.2025 19:15:10
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.
CVE-2025-27469
- EPSS 12.71%
- Published 08.04.2025 17:23:56
- Last modified 08.07.2025 19:06:37
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
CVE-2025-26679
- EPSS 0.07%
- Published 08.04.2025 17:23:55
- Last modified 09.07.2025 16:35:44
Use after free in RPC Endpoint Mapper Service allows an authorized attacker to elevate privileges locally.
CVE-2025-26676
- EPSS 0.06%
- Published 08.04.2025 17:23:54
- Last modified 09.07.2025 14:17:34
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26673
- EPSS 13.61%
- Published 08.04.2025 17:23:53
- Last modified 09.07.2025 16:36:18
Uncontrolled resource consumption in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to deny service over a network.
CVE-2025-26672
- EPSS 0.06%
- Published 08.04.2025 17:23:52
- Last modified 09.07.2025 14:10:52
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
CVE-2025-26671
- EPSS 0.1%
- Published 08.04.2025 17:23:51
- Last modified 09.07.2025 14:11:44
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.